CVE-2026-46090: ALSA: aloop: Fix peer runtime UAF during format-change stop
ALSA: aloop: Fix peer runtime UAF during format-change stop
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch 826af7fa62e3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch ALSA: aloop: Fix racy access at PCM trigger - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch ALSA: aloop: Fix peer runtime UAF during format-change stop
Event History
Frequently Asked Questions
What is the severity of CVE-2026-46090?
CVE-2026-46090 has a risk score of 44, indicating a critical vulnerability in the ALSA loopback subsystem.
What does CVE-2026-46090 affect?
CVE-2026-46090 affects the ALSA: aloop component of the Linux kernel.
How do I fix CVE-2026-46090?
To fix CVE-2026-46090, update your Linux kernel to the latest version that addresses this vulnerability.
What is the cause of CVE-2026-46090?
CVE-2026-46090 is caused by a use-after-free condition occurring during format changes in the ALSA loopback device.
When was CVE-2026-46090 published?
CVE-2026-46090 was published on May 27, 2026.